On September 22, 2026, the WordPress Security Team released WordPress 7.1.2, as well as security backports for every branch back to WordPress 4.7 to address a critical unauthenticated path traversal vulnerability. The issue is tracked as CVE-2026-87902 and has a CVSS v4.0 score of 9.2 (Critical). The vulnerability can allow an unauthenticated attacker to make WordPress include a readable PHP file from outside the active theme directory.
PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core
About this summary. This is a short, independently written summary of an article first published by Wordfence. Cyber Security News did not report or verify the underlying story. Read the original: https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/

Source attribution: headline and facts are from Wordfence (wordfence.com). Summary method: excerpt of the source description. See our source attribution policy.




